-
Alex Bodi pushes ahead with expansion: ALIX LASERS showroom planned for Bucharest
-
Quarantine, unease and rumours: Russian city grapples with plague scare
-
Fossil fuels off COP31 agenda as global output keeps rising
-
Taiwan says exports hit record in September on AI demand
-
Haze not 'a threat' to Singapore F1 race: organisers
-
Marc Marquez vows to 'attack' Martin's lead at Indonesian MotoGP
-
COP31 organisers say to seek 'ambitious' action with their text
-
Diplomats, schools in Saudi take safety measures after blasts heard: sources to AFP
-
Bartunkova thrashes Muchova to reach China Open semi-finals
-
In Beijing, EU trade envoy says deficit with China 'unsustainable'
-
Drone hits Yandex data centre, in first such attack on Russia
-
Sri Lanka's de Silva quits as Test captain
-
Oil prices surge and stocks sink on fresh inflation worries
-
Alcaraz feeling 'mentally fresh' ahead of Shanghai return
-
AI startup Manus raises $500m after Meta acquisition blocked by China
-
Israel drastically reduces British diplomatic presence in Jerusalem
-
From refuge to repatriations: Malaysia's Myanmar U-turn
-
Stocks fall further as oil surge fans fresh inflation worries
-
Morikawa says LIV players face 'business decision' after Rahm exit
-
North Korea demands South show 'utmost respect' to restore relations
-
Tenzing Norgay's son says Himalayas sending climate warning
-
Saudi says three dead in airport attacks claimed by Houthis
-
On your bike! Bottas opts for two wheels to reach Singapore GP
-
'Mad dream': New showcase for African film opens in London
-
Alcaraz, Sinner, Osaka commit to Australian Open '1 Point Slam'
-
All Blacks coach Rennie says Wallabies exit 'part of the game'
-
Dodgers beat Braves to advance in MLB playoffs, Rays oust Yankees
-
The growing protests against India's poll body - and PM Modi
-
'A sun as black as my lungs': how corruption crucified a polluted Albania city
-
Stocks fall further as oil spike fans fresh inflation worries
-
The British historian helping the French rediscover de Gaulle
-
Bad COP, worse COP? EU tempers hopes for UN climate summit
-
Dodgers beat Braves to advance, Guardians survive in MLB playoffs
-
Rookie Henry named in Wallabies midfield to face All Blacks
-
Latin American, Caribbean women top Nobel literature buzz
-
Housing crisis set to dominate Spain's snap election
-
US says Fiji-based Chinese official paid bribes for Beijing
-
Gas, health care, utilities: high costs squeeze US midterm voters
-
After botched US execution, Christa Pike was nearly taken off life support
-
New Zealand Rugby seeks injunction over PNG Chiefs name
-
Guinea-Bissau junta urges military unit loyal to ex-president to disarm
-
Samsung expects 780% quarterly operating profit jump on AI boom
-
As species decline, green turtles offer glimmer of hope
-
Guardians survive with 9-3 win over White Sox
-
Brothers Scott and Beauden Barrett named to start for All Blacks
-
Saudi Arabia says 3 dead at airports after Houthis claim attacks
-
EU trade chief seeks to dial down China tensions
-
Stocks slide as oil sees volatile trading day over Iran war fears
-
'Never again Bolsonaro': thousands march ahead of Brazil election runoff
-
Microsoft pushes AI vision with new, expensive Surface laptop
Philippines health insurer hacked: What we know
Hackers have stolen the personal data of potentially millions of people from the Philippines's national health insurer, which has urged members to change their passwords after the "staggering" cyberattack.
The hackers have started releasing files including confidential memos from the stolen data to pressure the government into paying a $300,000 ransom.
Here is what we know so far about the attack, which was discovered by the Philippine Health Insurance Corporation (PhilHealth) on September 22:
What did the hackers steal?
PhilHealth and the government have yet to say exactly how many people have been impacted, but the insurer warned members in a notice that data such as addresses, phone numbers and insurance IDs was compromised.
As of June 30, according to its website, PhilHealth had more than 59 million direct and indirect contributors -- more than half the population of the Philippines.
PhilHealth asked members to monitor credit card transactions and change passwords, especially for financial services.
Separately, employee information was also stolen from the targeted computers.
The hackers released some of the data on the dark web, showing health memos and other information that a top government official described as confidential.
An investigation into the scale of the attack is ongoing, but the National Privacy Commission has described the amount of data stolen as "staggering".
Who are the hackers, and what do they want?
The Philippine government has referred to the attackers as the Medusa group, who have demanded $300,000 to restore access to PhilHealth computers and delete the stolen data.
MedusaLocker, first detected in late 2019, has been used to mainly target healthcare organisations and its creators took particular advantage of the emergency situation during the Covid-19 pandemic, according to a US government report.
The ransomware has been sold to criminal actors, and a US government cybersecurity advisory said its creator receives a cut of any ransom.
It was not clear if the Medusa group identified by the Philippines government is the creator of or an entity that purchased MedusaLocker.
How did they get the data?
On September 22, PhilHealth staff were unable to access a number of computers, which displayed a message saying hackers had locked the machines and encrypted the data.
The insurer shut down the affected systems to try and stop the attack from spreading, slowing or entirely shutting down some online services for days.
The government has so far not said exactly how hackers got access to the computers.
But in interviews with local media last week, senior PhilHealth official Israel Pargas said the insurer did not have an antivirus software at the time of the attack.
How has the government responded?
With a blunt 'No'. The Philippines does not pay ransom in any criminal cases, including cyberattacks, officials have said.
However, with hackers releasing more data from the stolen files, calls have grown for the government to conduct an audit of its cyber defences.
The National Privacy Commission said Saturday it has started an investigation into any potential lapses and data law violations by PhilHealth.
The NPC said its analysis of 734 GB of stolen data revealed "sensitive personal data", and warned the public that anyone who downloads this information could face criminal charges.
Q.Bulbul--SF-PST